UK-based fintech firm Revolut has admitted to accidentally leaking confidential user details to an unauthorized third party following deception by fake information requests originating from an authentic government agency’s email address.
According to a notice sent to impacted clients, the compromised records comprised personal identity and contact data, such as dates of birth, physical and email addresses, telephone numbers, and scanned government IDs like driver’s licenses and passports. The company’s notice further highlighted that identity verification selfies, bank statements, and payment histories might have been accessed as well.
A representative for Revolut informed that only a “limited” group of users was affected and noted that the firm had personally notified each one. However, Revolut declined to share the precise count of affected accounts, refrained from confirming if the leak targeted specific geographical locations, and withheld the identity of the government entity involved.
“Revolut recently detected a complex external social engineering scheme in which an unauthorized entity leveraged an official government domain email to submit deceptive requests for records,” the representative stated.
Upon discovering the deceit, Revolut immediately blacklisted the email address and notified the affected government organization, law enforcement authorities, and oversight bodies. The company emphasized that “Revolut systems and customer funds are unaffected.”
Headquartered in London, Revolut boasts over 80 million users worldwide and holds banking operations across upwards of 30 nations, based on its site. The financial technology company recently scaled its footprint in regions such as France, Mexico, India, and the UAE. Additionally, earlier this month, the U.S. Office of the Comptroller of the Currency issued conditional approval allowing Revolut to establish a national bank in the United States, targeting a launch in early 2027.
Prominent cryptocurrency security analyst ZachXBT shared details regarding Revolut’s breach notice sent to impacted users late Friday evening, pointing out that the breach seemingly focused on wealthy clients.










